SeniorDevSecOpsEngineer
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations
Company Overview
Pantheon Data (a Kenific Holding company) is a private, small business based in the Washington, DC, area. Pantheon Data was founded in 2011, initially providing acquisition and supply chain management services to the US Coast Guard. Our service offerings have grown in the past ten years, including infrastructure resiliency, contact center operations, information technology, software engineering, program management, strategic communications, engineering, and cybersecurity.
We have also grown our customer base to include commercial clients. The company has used this experience to expand our service offerings to other agencies within the Department of Homeland Security (DHS), the Department of Defense (DoD), and other Federal Civilian Agencies.
Pantheon Data is seeking a Senior Dev Sec Ops Engineer to design, build, and operate secure, cloud-native platforms in AWS Gov Cloud supporting ML-enabled workloads and applications that process CUI, PII, and PHI. Git Lab Ultimate is our Dev Sec Ops platform: you will own our Git Lab CI/CD architecture end to end - pipelines, runners, security scanning, policy enforcement, and compliance evidence - and lead the migration of existing repositories and pipelines onto it.
The role combines secure pipeline engineering with platform operations: hardened infrastructure as code, production Amazon EKS administered through Git Ops, and gated security controls that satisfy NIST 800-53, FedRAMP, and DoD SRG requirements while keeping delivery fast. Successful candidates can walk through pipelines and platforms they have personally built - stage design, security gates, runner architecture, failure modes, and the compliance evidence they produced.
Responsibilities- Git Lab CI/CD Engineering: Design, implement, and operate enterprise-grade Git Lab CI/CD pipelines, including multi-project/parent-child pipeline orchestration, environment promotion gates, protected branches and environments, and reusable pipeline templates and CI components.
- Git Lab Ultimate Security Suite: Deploy, configure, and tune the full Git Lab Ultimate security suite as required pipeline gates:
Advanced SAST, DAST, secret detection (including push protection), dependency scanning, container scanning, IaC scanning, license compliance, and API security - with findings triaged through the vulnerability management dashboard and merge request security widgets. - Policy-as-Code & Compliance Automation: Enforce security centrally using scan execution policies, merge request approval policies, compliance frameworks, and compliance pipelines so scanning is mandatory across all projects; maintain audit events and evidence packages that support ATO, POA&M, and continuous-monitoring activities.
- Software Supply Chain Security: Generate and manage SBOMs (CycloneDX), enforce dependency and license policies, sign and verify build artifacts and container images, and maintain a secure, traceable path from commit to production.
- Runners & Cloud Auth: Architect and operate Git Lab Runner fleets in Gov Cloud (autoscaling, isolation, hardened images) and implement keyless OIDC authentication from Git Lab to AWS IAM roles - no long-lived cloud credentials in CI.
- Secure Infrastructure: Design and maintain hardened AWS Gov Cloud environments with Terraform (modular design, remote state, multi-repo dependency ordering), aligned to NIST 800-53 and FedRAMP High baselines and DISA STIG/CIS benchmarks.
- Kubernetes & Git Ops: Manage lifecycle, networking, and security for production Amazon EKS clusters; orchestrate deployments with Helm and Git Ops tooling (Argo CD or Flux) for declarative state management; harden clusters, registries, and OCI image workflows.
- ML Workload Support: Deploy and scale containerized ML models and data pipelines; build observability (metrics, logging, alerting, tracing) for regulated, restricted-egress environments.
- Platform Migration: Lead the migration of repositories, pipelines, and integrations from Git Hub/Git Hub Actions to Git Lab, including translation of workflows, secrets strategy, branch protection parity, and developer enablement.
- Team Enablement: Mentor engineers on secure delivery practices, author runbooks and pipeline documentation, and partner with security and compliance teams on control implementation and assessment support.
- Bachelor's degree in Computer Science, Information Technology, Information Systems, Engineering, or a related technical field,froman ABETaccredited university.
- 5+ years in Dev Sec Ops /Dev Ops engineering with responsibility for production AWS environments. Plus an additional 5 years of experience in arelatedtechnical field.
- Deep, hands-on Git Lab expertise:
Git Lab CI/CD pipeline design at scale, Git Lab Ultimate security and compliance features (SAST/DAST/secret detection/dependency/container/IaC scanning, scan execution and approval policies, security dashboards), and Git Lab Runner administration. - Experience implementing gated…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).